Zlob trojan et p2p worm

Résolu
IcY -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Bonjour, jai eu le trojan zlob apres plusieurs tentatives jai reussi a men debarrasser partiellemement.tk jai aucun bleu screen,aucun icon gay fitish qui apparet sur mon bureau mais en faisant un scan avec zonealarme on detecte p2p worm win32 et kazaa lite goop 28 et jen ait p-e dautre de cache :(
alors voici mon scan de hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:44, on 2008-11-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Maxtor\Schedule2\schedul2.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\Setup_ver1.1431.0.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Maxtor\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
A voir également:

48 réponses

IcY
 
apres avoir cleaner avec les 2 cleaner ,desiactive et reactive et me cree un point de restauration ya pu rien a faire on aurais fini??? et quandtu dis changer les mots de passe tu parle tu de la passe de son compte en ligne ou bien ceux de lordi si cest lordi jen ait pas de passe
0
IcY
 
log de tcleaner

[ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\Combofix.txt: trouvé !
C:\Combofix: trouvé !
C:\Lop SD: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\Administrateur\Bureau\hijackthis.log: trouvé !
C:\Documents and Settings\Administrateur\Bureau\lopR.txt: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\SdFix.exe: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\HijackThis.lnk: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\OTMoveIt3.exe: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\Rsit.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

log de ccleaner(registe je sais pas si cetai snecessaire a envoyer)

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\system32\\ZoneLabs\\isafeif.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\system32\\ZoneLabs\\vetredir.dll"=dword:00000001

[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aa]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aa\OpenWithProgids]
"NeroShowTime.Files7.aa"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfosspeed]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfosspeed\OpenWithList]
"a"="setup.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfosspeed\OpenWithProgids]
"cfosspeedkeyfile"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.key]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.key\OpenWithList]
"a"="KeyViewer.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pl\OpenWithProgids]
"plfile"=hex(0):

[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@="C:\\Program Files\\Adobe\\Reader 9.0\\Acrobat\\AcroRd32.exe"

[HKEY_CLASSES_ROOT\ConnectionTester.CManager]
@="ConnectionTester.CManager"

[HKEY_CLASSES_ROOT\ConnectionTester.CManager\Clsid]
@="{E532CFB1-5EDD-4663-8C22-BCD67B5E5BD4}"

[HKEY_CLASSES_ROOT\ZAMailSafe\DefaultIcon]
@="C:\\Program Files\\Zone Labs\\ZoneAlarm\\UpdClient.exe,-279"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}]
@="SkinPlasma Object"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}]
@="Microsoft TreeView Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Control]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\ProgID]
@="COMCTL.TreeCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 2"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}\VersionIndependentProgID]
@="COMCTL.TreeCtrl"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}]
@="TreeView General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}]
@="Microsoft ProgressBar Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Control]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\MiscStatus\1]
@="172433"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\ProgID]
@="COMCTL.ProgCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 17"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}\VersionIndependentProgID]
@="COMCTL.ProgCtrl"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D8-850A-101B-AFC0-4210102A8DA7}]
@="Progress Bar General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{0713E8D8-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}]
@="SkinStatic Object"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}]
@="SkinMiscControls Object"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}]
@="Microsoft Slider Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Control]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\ProgID]
@="COMCTL.Slider.1"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 16"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}\VersionIndependentProgID]
@="COMCTL.Slider"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F4-EB8B-11CD-8820-08002B2F4F5A}]
@="Slider General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{373FF7F4-EB8B-11CD-8820-08002B2F4F5A}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}]
@="Microsoft ListView Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Control]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\ProgID]
@="COMCTL.ListViewCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 4"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}\VersionIndependentProgID]
@="COMCTL.ListViewCtrl"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}]
@="Microsoft ImageList Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Control]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\MiscStatus\1]
@="165009"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\ProgID]
@="COMCTL.ImageListCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 3"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}\VersionIndependentProgID]
@="COMCTL.ImageListCtrl"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D93-9D6A-101B-AFC0-4210102A8DA7}]
@="ImageList General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D93-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D96-9D6A-101B-AFC0-4210102A8DA7}]
@="Image Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{58DA8D96-9D6A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}]
@="SkinRadio Object"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB955-5C57-11CF-8993-00AA00688B10}]
@="ListView General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB955-5C57-11CF-8993-00AA00688B10}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB956-5C57-11CF-8993-00AA00688B10}]
@="ListView Sort Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB956-5C57-11CF-8993-00AA00688B10}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB957-5C57-11CF-8993-00AA00688B10}]
@="ListView Images Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB957-5C57-11CF-8993-00AA00688B10}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB958-5C57-11CF-8993-00AA00688B10}]
@="ListView Columns Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{5ACBB958-5C57-11CF-8993-00AA00688B10}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{6027C2D4-FB28-11CD-8820-08002B2F4F5A}]
@="Slider Appearance Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{6027C2D4-FB28-11CD-8820-08002B2F4F5A}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}]
@="Microsoft Toolbar Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Control]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\MiscStatus\1]
@="237969"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\ProgID]
@="COMCTL.Toolbar.1"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 12"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{612A8624-0FB3-11CE-8747-524153480004}\VersionIndependentProgID]
@="COMCTL.Toolbar"

[HKEY_CLASSES_ROOT\CLSID\{612A8628-0FB3-11CE-8747-524153480004}]
@="Toolbar General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{612A8628-0FB3-11CE-8747-524153480004}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}]
@="SkinButton Object"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{62823C20-41A3-11CE-9E8B-0020AF039CA3}]
@="Button Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{62823C20-41A3-11CE-9E8B-0020AF039CA3}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}]
@="SkinForm Object"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}]
@="Microsoft StatusBar Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Control]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\MiscStatus\1]
@="172433"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\ProgID]
@="COMCTL.SBarCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 1"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}\VersionIndependentProgID]
@="COMCTL.SBarCtrl"

[HKEY_CLASSES_ROOT\CLSID\{6B7E6393-850A-101B-AFC0-4210102A8DA7}]
@="StatusBar General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{6B7E6393-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{6B7E63A3-850A-101B-AFC0-4210102A8DA7}]
@="Panel Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{6B7E63A3-850A-101B-AFC0-4210102A8DA7}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}]
@="SkinImage Object"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}]
@="Microsoft TabStrip Control, version 5.0 (SP2)"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Control]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\ProgID]
@="COMCTL.TabStrip.1"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\ToolboxBitmap32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX, 10"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\TypeLib]
@="{6B7E6392-850A-101B-AFC0-4210102A8DA7}"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\Version]
@="1.3"

[HKEY_CLASSES_ROOT\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}\VersionIndependentProgID]
@="COMCTL.TabStrip"

[HKEY_CLASSES_ROOT\CLSID\{9ED94444-E5E8-101B-B9B5-444553540000}]
@="TabStrip General Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{9ED94444-E5E8-101B-B9B5-444553540000}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}]
@="SkinScrollBar Object"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{B66834C6-2E60-11CE-8748-524153480004}]
@="Tab Property Page Object"

[HKEY_CLASSES_ROOT\CLSID\{B66834C6-2E60-11CE-8748-524153480004}\InprocServer32]
@="C:\\Program Files\\Malwarebytes' Anti-Malware\\COMCTL32.OCX"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}]
@="ActiveSkin 4.3 Control"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Control]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\MiscStatus\1]
@="132497"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\ProgID]
@="ActiveSkin4.Skin2.1"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\ToolboxBitmap32]
@="C:\\WINDOWS\\system32\\actskn43.ocx, 206"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\1]
@="&Load Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\2]
@="&Save Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\3]
@="&Edit Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\4]
@="&Delete Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\5]
@="&About..,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\VersionIndependentProgID]
@="ActiveSkin4.Skin2"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}]
@="SkinLabel 4.3 Control"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\Control]

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\MiscStatus\1]
@="139665"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\ProgID]
@="ActiveSkin4.SkinLabel2.1"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\ToolboxBitmap32]
@="C:\\WINDOWS\\system32\\actskn43.ocx, 119"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\VersionIndependentProgID]
@="ActiveSkin4.SkinLabel2"

[HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}]
@="SkinTab Object"

[HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}]
@="SkinFreeForm Object"

[HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}]
@="SkinFrame Object"

[HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\InprocServer32]
@="C:\\WINDOWS\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}]
@="ISearch"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\TypeLib]
"Version"="1.0"
@="{47A7A4B0-2723-41BA-865E-EBBB7081A602}"

[HKEY_CLASSES_ROOT\Interface\{915DA835-02FE-4953-92FA-624BDF5D85AB}]
@="IUserHelper"

[HKEY_CLASSES_ROOT\Interface\{915DA835-02FE-4953-92FA-624BDF5D85AB}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{915DA835-02FE-4953-92FA-624BDF5D85AB}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{915DA835-02FE-4953-92FA-624BDF5D85AB}\TypeLib]
@="{19D52A9A-379C-4720-BA00-3D396ECD24D7}"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{D775A119-EAC2-4F28-B06E-8AC16F2695DA}]
@="IiPodManagerUI"

[HKEY_CLASSES_ROOT\Interface\{D775A119-EAC2-4F28-B06E-8AC16F2695DA}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{D775A119-EAC2-4F28-B06E-8AC16F2695DA}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{D775A119-EAC2-4F28-B06E-8AC16F2695DA}\TypeLib]
@="{19D52A9A-379C-4720-BA00-3D396ECD24D7}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WgaNotify]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{125F0ACC-D3FC-402B-8D96-27F6E46D00D5}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45D68F08-56A0-4412-BB0F-8492BE978AC7}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{558CD0A7-0548-4220-88FE-01CC1477DF61}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{57ECFB4D-FE11-491A-9AA0-0AF7C3ABC51D}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,fc,49,01,00,00,00,00,80,b0,94,\
02,c8,9f,c8,01,06,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,45,00,53,00,45,00,54,\
00,5c,00,45,00,53,00,45,00,54,00,20,00,4e,00,4f,00,44,00,33,00,32,00,20,00,\
41,00,6e,00,74,00,69,00,76,00,69,00,72,00,75,00,73,00,5c,00,65,00,67,00,75,\
00,69,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5AC9F44E-06C7-41E3-A464-37177AB9105D}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7C3E3706-8FBD-4169-9726-0A47FBF9D32A}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7D974ACA-4EE5-412C-8E6A-A5B57B305727}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,fc,8c,01,00,00,00,00,80,be,41,\
b2,d3,a0,c8,01,05,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,45,00,53,00,45,00,54,\
00,5c,00,45,00,53,00,45,00,54,00,20,00,4e,00,4f,00,44,00,33,00,32,00,20,00,\
41,00,6e,00,74,00,69,00,76,00,69,00,72,00,75,00,73,00,5c,00,65,00,67,00,75,\
00,69,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{81A60A13-224D-4637-8203-3EAC03B121A4}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,70,e7,0b,00,00,00,00,30,d0,c3,\
b0,d3,9f,c8,01,09,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,61,00,78,00,74,\
00,6f,00,72,00,5c,00,4d,00,61,00,78,00,42,00,6c,00,61,00,73,00,74,00,5c,00,\
4d,00,61,00,78,00,42,00,6c,00,61,00,73,00,74,00,2e,00,65,00,78,00,65,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8AEA4BE2-2B52-41C0-BB7D-9F2D17AF1036}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,1c,4f,3b,00,00,00,00,00,00,00,\
00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Tu as fait la recherche avec ToolsCleaner mais pas la suppression.
0
IcY
 
bonjour
pourtant apres le scan jai supprimer jen suis sure meme. pk tu dis jai pas supprime???
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Car dans le rapport, il n'y a pas de partie Suppression.
0
IcY
 
si je me fis aux logs mettons ca laurais pas supprime cest juste les log et les .exe de mes logiciels qui a permi a me debarrasse de mon virus. ca ferais quoi ca serais pas supprime mes logs et les .exe des logiciel???
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Rien compris.
0
IcY
 
ma question etais ca fais quoi si jaurais pas supprime avec tcleaner si cest juste des logs des logiciels et les .exe des logiciel qui supprime??? de toute facon jai refais un scan et voila mes logs

[ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\Combofix.txt: trouvé !
C:\Combofix: trouvé !
C:\Lop SD: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\Administrateur\Bureau\hijackthis.log: trouvé !
C:\Documents and Settings\Administrateur\Bureau\lopR.txt: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\SdFix.exe: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\HijackThis.lnk: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\OTMoveIt3.exe: trouvé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\Rsit.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\SdFix.exe: supprimé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\HijackThis.lnk: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Documents and Settings\Administrateur\Bureau\hijackthis.log: supprimé !
C:\Documents and Settings\Administrateur\Bureau\lopR.txt: supprimé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\OTMoveIt3.exe: supprimé !
C:\Documents and Settings\Toeb\Bureau\logiciels pour virus.trojan\Rsit.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Combofix: supprimé !
C:\Lop SD: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
ToolCleaner, c'est pour supprimer les "tools" style OTMoveIt3, ComboFix, etc...

Le rapport est OK.
0
IcY
 
alors on aurais tout termine en principe??? jai cree un back up aussi alors merci mister comme jai dis + tot cest tres tres apprecie:) ca ma fais plaisir de faire affaire avec toi tu fais bien ca:)

IcY
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Et encore, en ce moment, je rame, je suis en train de changer mes méthodes donc il me faut un temps d'adaptation ;)

Des questions ?
0
IcY
 
non je crois jai pas de question tout va bien de mon cote:) tu pourras fermer le sujet;)

alors merci bonne fin de journee.si jai un autre soucis et tu vois IcY fais vite et reponds lui:) hihihi

ton aide a ete apprecie merci encore:):):)

IcY
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Le sujet a été passé en résolu ;)

Bonne soirée.

Willy.
0